Cache Attacks Enable Bulk Key Recovery on the Cloud
eprint.iacr.org
eprint.iacr.org
Somehow I wonder about that. Spear phishing is very effective and the software itself isn't exactly perfect either. Either very few people are even trying, or something does not add up.
[1] https://www.usenix.org/legacy/events/sec09/tech/full_papers/... "We implemented these side-channel attacks and our best practical attack fully recovered 95% of the keystrokes of a PS/2 keyboard at a distance up to 20 meters, even through walls. We tested 12 different keyboard models bought between 2001 and 2008 (PS/2, USB, wireless and laptop)."
As +Andreas Schou said in his share, "Okay. That's it. I give up. Security is impossible."
> Libgcrypt 1.6.3 update: Libgcrypt recently patched this vulnerability by mak- ing the sliding window multiplication table accesses indistinguishable from each other. Thus, an update to the latest version of the library avoids the leakage ex- ploited in this work albeit only for ciphers using sliding window exponentiation.
So it's already patched, assuming you patch (they say 55% of the hosts in their AWS region hasn't been patched in a year).
Nonetheless, there's novel work and interesting insights in the paper, and it's a short read.
I disagree. It's possible to make good use of public infrastructure without handling any important secrets on public machines. Under certain threat models, you have to assume public infrastructure is vulnerable to coercion of the providers and side-channel attacks from co-tenants. As we are beginning to see, providers have the tools and processes to comply with coercive demands (RAM/disk dumps) and co-tenants can feasibly succeed in obtaining secrets via side-channel attacks.
Under models like this, public infrastructure is still useful for storing and routing encrypted information, enabling NAT traversal, and distributing signed material which can be authenticated at the client.
If that is true, would this be mitigated by "virtual clouds" (things like https://aws.amazon.com/vpc/) or is that just taking place at the network layer?
Crypto libraries can be fixed to prevent side-channel attacks like this. The article says that libgcrypt has already been patched.
The host machine has it all, anyone who has access to the host can clone your entire VPS at will, RAM and all, what security are you talking about?
(you can't be sure if you rent a physical server either, but that's another topic)
Besides, while the paper talks about extracting RSA keys, nothing prevents extraction of any other kind of data using the same methodology. So even if people with host acccess overlook you, nothing is secure from your neighbours. It's just that encryption keys are for some reason considered more newsworthy. Maybe because once they get access to your VPS via them, the rest is even more trivial.